Raise your hand if you’ve heard the myth, “Android isn’t secure.” Android phones, such as the Samsung Galaxy, unlock new ways of working. But, as an IT admin, you may worry about the security—after all, work data is critical. However, outdated concerns can hold your business back from unlocking its full potential. The truth is, … Read More “Securing the Open Android Ecosystem with Samsung Knox – The Hacker News” »
Author: [email protected] (The Hacker News)
Microsoft Teams Flaws Allowed Attackers to Fake Identities, Rewrite Chats – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
Microsoft Teams vulnerabilities let attackers impersonate users, edit chat history, and spoof calls before Microsoft issued security fixes in late 2025. – Read More – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
Mysterious ‘SmudgedSerpent’ Hackers Target U.S. Policy Experts Amid Iran–Israel Tensions – The Hacker News
A never-before-seen threat activity cluster codenamed UNK_SmudgedSerpent has been attributed as behind a set of cyber attacks targeting academics and foreign policy experts between June and August 2025, coinciding with heightened geopolitical tensions between Iran and Israel. “UNK_SmudgedSerpent leveraged domestic political lures, including societal change in Iran and investigation into the – Read More – … Read More “Mysterious ‘SmudgedSerpent’ Hackers Target U.S. Policy Experts Amid Iran–Israel Tensions – The Hacker News” »
10 Successful Marketplaces Built on Sharetribe: Lessons Learned – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
The marketplace revolution is here, and it’s transforming how we buy, sell, and share everything from vintage furniture… – Read More – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
Three of Anthropic’s Claude Desktop extensions were vulnerable to command injection – flaws that have now been fixed – Read More –
Juniper Research predicts a $9bn drop in losses to SMS fraud next year – Read More –
Zscaler estimates 239 malicious Android apps made it onto the official Play store over the past year – Read More –
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added two security flaws impacting Gladinet and Control Web Panel (CWP) to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The vulnerabilities in question are listed below – CVE-2025-11371 (CVSS score: 7.5) – A vulnerability in files or directories … Read More “CISA Adds Gladinet and CWP Flaws to KEV Catalog Amid Active Exploitation Evidence – The Hacker News” »
Google Expands Chrome Autofill to Passports and Licenses, But Is It Safe? – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
Google Chrome browser’s new enhanced autofill feature can now remember and automatically fill in personal data such as… – Read More – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
Apple addresses more than 100 vulnerabilities in security updates for iPhones, Macs and iPads – CyberScoop
Apple disclosed an exceptionally high number of vulnerabilities in core services and components used across its most popular devices, as the tech giant addressed 105 vulnerabilities in MacOS 26.1 and 56 vulnerabilities with the release of iOS 26.1 and iPadOS 26.1. The company’s latest security update includes some flaws that affect software spanning iPhones, Macs … Read More “Apple addresses more than 100 vulnerabilities in security updates for iPhones, Macs and iPads – CyberScoop” »
North Korean companies, people sanctioned for money laundering from cybercrime, IT worker schemes – CyberScoop
The Treasury Department on Tuesday sanctioned eight people and two companies it accused of laundering money obtained from cybercrime and IT worker schemes to fund North Korean government objectives. According to the department, over the last three years North Korea-linked cybercriminals have stolen over $3 billion, mostly in cryptocurrency. In addition, it said, North Korean … Read More “North Korean companies, people sanctioned for money laundering from cybercrime, IT worker schemes – CyberScoop” »
A Cybercrime Merger Like No Other — Scattered Spider, LAPSUS$, and ShinyHunters Join Forces – The Hacker News
The nascent collective that combines three prominent cybercrime groups, Scattered Spider, LAPSUS$, and ShinyHunters, has created no less than 16 Telegram channels since August 8, 2025. “Since its debut, the group’s Telegram channels have been removed and recreated at least 16 times under varying iterations of the original name – a recurring cycle reflecting platform … Read More “A Cybercrime Merger Like No Other — Scattered Spider, LAPSUS$, and ShinyHunters Join Forces – The Hacker News” »
SesameOp Backdoor Abused OpenAI Assistants API for Remote Access – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
Microsoft researchers found the SesameOp backdoor using OpenAI’s Assistants API for remote access, data theft, and command communication. – Read More – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
Bugcrowd, a company known for its work in bug bounty and vulnerability disclosure, has announced the acquisition of Mayhem Security, an AI-driven offensive security firm. The terms of the deal were not disclosed. Organizations are dealing with more complicated cybersecurity risks as they build software faster, add more APIs, and work with many suppliers. Traditional … Read More “Bugcrowd acquires Mayhem Security to advance AI-powered security testing – CyberScoop” »
Nine people have been arrested in connection with a coordinated law enforcement operation that targeted a cryptocurrency money laundering network that defrauded victims of €600 million (~$688 million). According to a statement released by Eurojust today, the action took place between October 27 and 29 across Cyprus, Spain, and Germany, with the suspects arrested on … Read More “Europol and Eurojust Dismantle €600 Million Crypto Fraud Network in Global Sweep – The Hacker News” »
Nine alleged crypto scammers arrested in Cyprus, Germany and Spain – Read More –
Details have emerged about a now-patched critical security flaw in the popular “@react-native-community/cli” npm package that could be potentially exploited to run malicious operating system (OS) commands under certain conditions. “The vulnerability allows remote unauthenticated attackers to easily trigger arbitrary OS command execution on the machine running react-native-community/cli’s – Read More – The Hacker News
Instead of relying on more traditional methods, the backdoor exploits OpenAI’s Assistants API for command-and-control communications – Read More –
Microsoft Teams Bugs Let Attackers Impersonate Colleagues and Edit Messages Unnoticed – The Hacker News
Cybersecurity researchers have disclosed details of four security flaws in Microsoft Teams that could have exposed users to serious impersonation and social engineering attacks. The vulnerabilities “allowed attackers to manipulate conversations, impersonate colleagues, and exploit notifications,” Check Point said in a report shared with The Hacker News. Following responsible disclosure in March – Read More … Read More “Microsoft Teams Bugs Let Attackers Impersonate Colleagues and Edit Messages Unnoticed – The Hacker News” »
Scattered Spider, ShinyHunters and LAPSUS$ have formed an enhanced coordinated threat network for extortion efforts – Read More –
2025 Insider Risk Report Finds Most Organizations Struggle to Detect and Predict Insider Risks – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
Baltimore, USA, 4th November 2025, CyberNewsWire – Read More – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
Bob Flores, Former CTO of the CIA, Joins Brinker – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
Delaware, United States, 4th November 2025, CyberNewsWire – Read More – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
UK Court Delivers Split Verdict in Getty Images vs. Stability AI Case – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
In January 2023, Getty Images filed a major lawsuit in the UK High Court against Stability AI, an… – Read More – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
DragonForce, a ransomware group using Conti’s code, has adopted a cartel model to expand and recruit – Read More –
ReliaQuest data reveals identity issues were responsible for 44% of cloud security alerts in Q3 – Read More –
Threat actors are leveraging weaponized attachments distributed via phishing emails to deliver malware likely targeting the defense sector in Russia and Belarus. According to multiple reports from Cyble and Seqrite Labs, the campaign is designed to deploy a persistent backdoor on compromised hosts that uses OpenSSH in conjunction with a customized Tor hidden service that … Read More “Operation SkyCloak Deploys Tor-Enabled OpenSSH Backdoor Targeting Defense Sectors – The Hacker News” »
Ransomware is malicious software designed to block access to a computer system or encrypt data until a ransom is paid. This cyberattack is one of the most prevalent and damaging threats in the digital landscape, affecting individuals, businesses, and critical infrastructure worldwide. A ransomware attack typically begins when the malware infiltrates a system through various … Read More “Ransomware Defense Using the Wazuh Open Source Platform – The Hacker News” »
China-Linked Hackers Target Cisco Firewalls in Global Campaign – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
New reports show China-based hackers are targeting US federal, state, and global government networks via unpatched Cisco firewalls. Get the full details and necessary steps to secure devices. – Read More – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
Digital thieves have got away with over $120m stolen from popular decentralized finance protocol Balancer – Read More –
U.S. Prosecutors Indict Cybersecurity Insiders Accused of BlackCat Ransomware Attacks – The Hacker News
Federal prosecutors in the U.S. have accused a trio of allegedly hacking the networks of five U.S. companies with BlackCat (aka ALPHV) ransomware between May and November 2023 and extorting them. Ryan Clifford Goldberg, Kevin Tyler Martin, and an unnamed co–conspirator (aka “Co-Conspirator 1”) based in Florida, all U.S. nationals, are said to have used … Read More “U.S. Prosecutors Indict Cybersecurity Insiders Accused of BlackCat Ransomware Attacks – The Hacker News” »
Google’s artificial intelligence (AI)-powered cybersecurity agent called Big Sleep has been credited by Apple for discovering as many as five different security flaws in the WebKit component used in its Safari web browser that, if successfully exploited, could result in a browser crash or memory corruption. The list of vulnerabilities is as follows – CVE-2025-43429 … Read More “Google’s AI ‘Big Sleep’ Finds 5 New Vulnerabilities in Apple’s Safari WebKit – The Hacker News” »
Microsoft Detects “SesameOp” Backdoor Using OpenAI’s API as a Stealth Command Channel – The Hacker News
Microsoft has disclosed details of a novel backdoor dubbed SesameOp that uses OpenAI Assistants Application Programming Interface (API) for command-and-control (C2) communications. “Instead of relying on more traditional methods, the threat actor behind this backdoor abuses OpenAI as a C2 channel as a way to stealthily communicate and orchestrate malicious activities within the compromised – … Read More “Microsoft Detects “SesameOp” Backdoor Using OpenAI’s API as a Stealth Command Channel – The Hacker News” »
Microsoft Fixes Long-Standing ‘Update and Shut Down’ Bug in Windows 11 – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
Your Windows 11 PC will finally shut down! Learn about the KB5067036 update that fixes the decades-old restart glitch, plus new features like faster search and simpler update names. – Read More – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
The Office of Personnel Management plans to collaborate on a “mass deferment” for a cyber scholarship-for-service program after the government shutdown ends, a spokesman said Monday, as scholarship recipients have sounded fears about being on the hook for their schooling costs during federal hiring freezes and budget cuts. The National Science Foundation (NSF) leads and … Read More “OPM plans to give CyberCorps members more time to find jobs after shutdown ends – CyberScoop” »
Prosecutors allege incident response pros used ALPHV/BlackCat to commit string of ransomware attacks – CyberScoop
Federal prosecutors allege that three cybersecurity professionals, whose job was to help companies respond to ransomware attacks, instead carried out their own ransomware schemes against five U.S. businesses in 2023. Ryan Clifford Goldberg, Kevin Tyler Martin and an unnamed co–conspirator — all U.S. nationals — began using ALPHV, also known as BlackCat, ransomware to attack … Read More “Prosecutors allege incident response pros used ALPHV/BlackCat to commit string of ransomware attacks – CyberScoop” »
New Dante Spyware Linked to Rebranded Hacking Team, Now Memento Labs – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
Kaspersky researchers uncovered Operation ForumTroll, an attack campaign utilising the new ‘Dante’ spyware developed by Memento Labs, the rebranded Hacking Team. The attacks used a Chrome zero-day vulnerability (CVE-2025-2783) and COM hijacking for persistence, confirming the continued deployment of advanced surveillance tools by the controversial Italian firm. – Read More – Hackread – Cybersecurity News, … Read More “New Dante Spyware Linked to Rebranded Hacking Team, Now Memento Labs – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More” »
Malicious VSX Extension “SleepyDuck” Uses Ethereum to Keep Its Command Server Alive – The Hacker News
Cybersecurity researchers have flagged a new malicious extension in the Open VSX registry that harbors a remote access trojan called SleepyDuck. According to Secure Annex’s John Tuckner, the extension in question, juan-bianco.solidity-vlang (version 0.0.7), was first published on October 31, 2025, as a completely benign library that was subsequently updated to version 0.0.8 on November … Read More “Malicious VSX Extension “SleepyDuck” Uses Ethereum to Keep Its Command Server Alive – The Hacker News” »
6 Reasons Occupancy Monitoring Is Key for Energy Efficiency – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
Today, with the world more conscious than ever about the conservation of energy, efficiency becomes even more critical.… – Read More – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
Cloud security company Zscaler announced Monday it has acquired SplxAI, an artificial intelligence security platform, in a move to strengthen its ability to protect enterprise AI assets. Terms were not disclosed. Zscaler said the purchase is aimed at enhancing its zero-trust security offerings by integrating Splx’s technology for AI asset discovery, automated red-teaming, and governance. … Read More “Zscaler adds more AI to its offerings with Splx acquisition – CyberScoop” »
CISA and NSA have released a blueprint to enhance Microsoft Exchange Server security against cyber-attacks – Read More –
Flaws in Windows Graphics Device Interface (GDI) have been identified that allow remote code execution and information disclosure – Read More –
Proofpoint researchers have observed recent hacking campaigns supporting cargo theft – Read More –
Cybercriminals Exploit Remote Monitoring Tools to Infiltrate Logistics and Freight Networks – The Hacker News
Bad actors are increasingly training their sights on trucking and logistics companies with an aim to infect them with remote monitoring and management (RMM) software for financial gain and ultimately steal cargo freight. The threat cluster, believed to be active since at least June 2025 according to Proofpoint, is said to be collaborating with organized … Read More “Cybercriminals Exploit Remote Monitoring Tools to Infiltrate Logistics and Freight Networks – The Hacker News” »
North Korean Hackers Caught on Video Using AI Filters in Fake Job Interviews – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
North Korean hackers from the Famous Chollima group used AI deepfakes and stolen identities in fake job interviews to infiltrate crypto and Web3 companies. – Read More – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
The Evolution of SOC Operations: How Continuous Exposure Management Transforms Security Operations – The Hacker News
Security Operations Centers (SOC) today are overwhelmed. Analysts handle thousands of alerts every day, spending much time chasing false positives and adjusting detection rules reactively. SOCs often lack the environmental context and relevant threat intelligence needed to quickly verify which alerts are truly malicious. As a result, analysts spend excessive time manually triaging alerts, the … Read More “The Evolution of SOC Operations: How Continuous Exposure Management Transforms Security Operations – The Hacker News” »
⚡ Weekly Recap: Lazarus Hits Web3, Intel/AMD TEEs Cracked, Dark Web Leak Tool & More – The Hacker News
Cyberattacks are getting smarter and harder to stop. This week, hackers used sneaky tools, tricked trusted systems, and quickly took advantage of new security problems—some just hours after being found. No system was fully safe. From spying and fake job scams to strong ransomware and tricky phishing, the attacks came from all sides. Even encrypted … Read More “⚡ Weekly Recap: Lazarus Hits Web3, Intel/AMD TEEs Cracked, Dark Web Leak Tool & More – The Hacker News” »
Sixty million school children’s personal information exposed. Thousands of flights canceled. A venerated retailer brought to its knees. Dire warnings from public officials about urgent threats to our national security. This isn’t speculative fiction. These are all real incidents that have happened in the last year. The stakes in cyberspace are high and growing, especially … Read More “Don’t let Congress punt on cyber insurance reform – CyberScoop” »
YouTube ‘Ghost Network’ Spreads Infostealer via 3,000 Fake Videos – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
Check Point Research exposed a sophisticated, role-based operation called the YouTube Ghost Network, distributing dangerous Lumma and Rhadamanthys Infostealer malware. Learn how cybercriminals use hijacked channels and bots to triple malicious video output and steal user credentials. – Read More – Hackread – Cybersecurity News, Data Breaches, Tech, AI, Crypto and More
Researchers Uncover BankBot-YNRK and DeliveryRAT Android Trojans Stealing Financial Data – The Hacker News
Cybersecurity researchers have shed light on two different Android trojans called BankBot-YNRK and DeliveryRAT that are capable of harvesting sensitive data from compromised devices. According to CYFIRMA, which analyzed three different samples of BankBot-YNRK, the malware incorporates features to sidestep analysis efforts by first checking its running within a virtualized or emulated environment – Read … Read More “Researchers Uncover BankBot-YNRK and DeliveryRAT Android Trojans Stealing Financial Data – The Hacker News” »
The North Korea-linked threat actor known as Kimsuky has distributed a previously undocumented backdoor codenamed HttpTroy as part of a likely spear-phishing attack targeting a single victim in South Korea. Gen Digital, which disclosed details of the activity, did not reveal any details on when the incident occurred, but noted that the phishing email contained … Read More “New HttpTroy Backdoor Poses as VPN Invoice in Targeted Cyberattack on South Korea – The Hacker News” »